Personal context stays person-scoped.

Learning happens at the population level, and it never determines an individual's access.

SOC 2 Type 2

Independently audited controls. Additional frameworks are scoped to what your programs require, as part of pilot design.

Live posture in the trust center

Three data layers.

01

Person-scoped context

Identity, authorized attributes, and the task-specific information CASEY derives to complete the task.

never aggregated

02

Task and outcome record

What was requested, what was authorized, what happened, and what was verified.

never aggregated

03

De-identified cohort insight

What completed outcomes reveal about where services work and where gaps remain.

aggregates across people

What happens to a record.

  1. Created for an authorized task
  2. Used only within that purpose
  3. Minimum necessary crosses a boundary, with the person's authorization
  4. Outcome verified and recorded
  5. Expires under its retention rule
Capability-scoped authority
Every task runs with only the context and authority it requires. Read, write and submit permissions are scoped independently.
Retention by purpose
Task data remains only as long as the workflow needs it.
Non-adverse use
Cohort insight may improve provision, never deny, restrict or adversely price access.
Minimum cohort threshold
Set by re-identification risk. Nothing is released below it.

Personal data is never sold. Providers pay for outcomes, not placement.

Security documentation.

Control-by-control detail on encryption, access, audit logging, retention and subprocessors is provided under our security documentation, with exact answers rather than summaries.